CVE-2021-3563

Incorrect Authorization in pypi/keystone

Identifiers

GHSA-cc99-whm5-mmq3, CVE-2021-3563

Package Slug

pypi/keystone

Vulnerability

Incorrect Authorization

Description

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.

Affected Versions

All versions up to 21.0.0

Solution

Unfortunately, there is no solution available yet.

Last Modified

2022-09-19

source